nerdexam
Fortinet

NSE7_EFW-7.2 · Question #37

Refer to the exhibit, which shows a network diagram. Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

The correct answer is C. Set route-overlap to either use-new or use-old. To ensure that only one remote site is connected at any given time in an IPsec VPN scenario, you should use route-overlap with the option to either use-new or use-old. This setting dictates which routes are preferred and how overlaps in routes are handled, allowing for one…

FortiGate VPN

Question

Refer to the exhibit, which shows a network diagram. Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

Exhibit

NSE7_EFW-7.2 question #37 exhibit

Options

  • ASet route-overlap to allow.
  • BSet single-source to enable
  • CSet route-overlap to either use-new or use-old
  • DSet net-device to enable

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    84% (31)
  • D
    5% (2)

Explanation

To ensure that only one remote site is connected at any given time in an IPsec VPN scenario, you should use route-overlap with the option to either use-new or use-old. This setting dictates which routes are preferred and how overlaps in routes are handled, allowing for one connection to take precedence over the other (C).

Topics

#IPsec phase 2#route-overlap#dial-up VPN#single connection

Community Discussion

No community discussion yet for this question.

Full NSE7_EFW-7.2 Practice